@nx/gradle 23.2.1 appears to be a healthy, actively maintained, organization-backed package with very strong release cadence, current repository activity, broad contributor participation, build provenance, security tooling, and a clear license. The package artifact includes type declarations and substantial compiled functionality, while repository tests and changelog coverage compensate for their absence from the artifact. The main adoption caveat is that the README identifies the Gradle plugin as experimental and the recent prerelease share is high, so APIs may change; workflow permission hygiene also has some gaps, but no severe supply-chain or abandonment indicators are present.
92%
Total Score
100
100
95
90
100
Six workflows lack top-level permissions declarations and one workflow has top-level write permissions, leaving some least-privilege ambiguity despite six workflows declaring read-only permissions.
The assessed version is a stable major release and not a prerelease, but 70% of recent versions are prereleases, so release-level API churn remains a caution for dependents.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-225378 New @nx/gradle is vulnerable to OS Command Injection in versions 21.0.0 - 22.7.8 and 23.0.0 - 23.1.1. | 21.0.0 - 22.7.823.0.0 - 23.1.1 | High |
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.3.0 | — | — |
@nx/devkit Version 23.2.1 | — | — |
toml-eslint-parser Version ^0.10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.